More jobs:
Senior VAPT Practice Head
Job in
560001, Vasanthanagar, Karnataka, India
Listed on 2026-09-05
Listing for:
EC-Council
Full Time
position Listed on 2026-09-05
Job specializations:
-
IT/Tech
Cybersecurity, IT Consultant
Job Description & How to Apply Below
Job Title:
Senior VAPT Practice Head
Location:
Candidate should be willing to relocate to Kuala Lumpur
EC-Council is the world's largest cyber security technical certification body. We operate in 145 countries globally and we are the owner and developer of various world-famous cyber security programs. We are proud to have trained and certified over 400,000 information security professionals globally that have influenced the cyber security mindset of countless organizations worldwide.
Visit us on (Use the "Apply for this Job" box below)..org
Job Summary
The Senior VAPT Practice Head is a strategic leadership role responsible for the end-to-end lifecycle of the Vulnerability Assessment and Penetration Testing (VAPT) business unit. This individual will act as the architect of our testing methodologies, the driver of operational delivery excellence, and the primary technical ambassador for our clients.
The ideal candidate is a subject matter expert in offensive security who can transition seamlessly from deep-dive technical reviews to high-level strategic discussions with C-suite stakeholders. You will be responsible for scaling the practice, ensuring the highest quality of deliverables, and driving revenue through technical pre-sales and relationship management.
Key Responsibilities
Practice Management & Strategy (Growth & Innovation)
Service
Roadmap:
Define and execute the long-term vision for the VAPT practice, including expanding service lines (e.g., Red Teaming, Cloud Security, Dev Sec Ops , API Security).
Methodology Development:
Establish and continuously evolve standardized testing frameworks based on industry standards (OWASP, NIST, OSSTMM, PTES) to ensure consistent, high-quality results.
Resource & Talent Management:
Lead recruitment, mentoring, and technical training for a team of penetration testers. Build a culture of continuous learning and research.
Tooling & Automation:
Evaluate, implement, and manage the security testing stack (automated scanners, manual exploitation tools, and custom-built scripts) to increase efficiency and coverage.
P&L Responsibility:
Manage the practice budget, optimize resource utilization, and drive profitability through efficient delivery models.
Delivery Management (Excellence & Quality Assurance)
Operational Oversight:
Oversee the end-to-end execution of all VAPT engagements, ensuring projects are delivered on time, within scope, and according to agreed-upon SLAs.
Quality Control:
Act as the final technical authority for all deliverables. Perform rigorous reviews of technical reports to ensure findings are accurate, risks are clearly articulated, and remediation advice is actionable.
Risk Management:
Ensure all testing activities are conducted within the bounds of legal and ethical frameworks, managing the risks associated with high-impact testing environments.
Continuous Improvement:
Implement feedback loops from clients and post-engagement reviews to drive iterative improvements in delivery processes.
Customer Engagement & Pre-Sales (Consulting & Revenue)
Technical Pre-Sales:
Partner with the sales team to lead technical discovery sessions, define project scopes, provide complex estimations, and draft technical proposals/RFPs.
Client Advisory:
Act as a trusted advisor to clients, translating complex technical vulnerabilities into business-level risk intelligence for CISOs and Board members.
Relationship Management:
Maintain strong, long-term relationships with key accounts, identifying opportunities for upselling, cross-selling, and service expansion.
Incident Response/Crisis Consulting:
Serve as the lead technical consultant during critical security incidents or high-stakes compliance audits involving client infrastructure.
Required Qualifications & Skills
Technical Expertise
Advanced Penetration Testing:
Deep expertise in Web Application, Mobile (iOS/Android), Network, Cloud (AWS/Azure/GCP), API, and Wireless security testing.
Offensive Security Mastery:
Proficiency with industry-standard tools (Burp Suite Professional, Metasploit, Nessus, Nmap, Cobalt Strike, etc.) and the ability to develop custom automation scripts (Python, Bash, or Go).
Security Frameworks:
Expert knowledge of OWASP Top 10, NIST…
Position Requirements
10+ Years
work experience
Note that applications are not being accepted from your jurisdiction for this job currently via this jobsite. Candidate preferences are the decision of the Employer or Recruiting Agent, and are controlled by them alone.
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search:
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search:
Search for further Jobs Here:
×